|
|||||||
| Tutorials & Guides Contributions welcome! Please check the rules & guidelines for posting |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
I have never gotten any of the bluetooth BS to work. Awesome tutorial though!
__________________
I felt like bending the bars back, and ripping out the window frames and eating them. yes, eating them! Leaping, leaping, leaping! Colonics for everyone! All right! You dumb*sses. I'm a mental patient. I'm *supposed* to act out! |
|
||||
|
Finally and to say merry xmas here it is, how to turn an ordinary USB dongle with a Cambridge Silicon Radio chipset into the FTS4BT sniffing dongle
Before we begin I would like to say I do not hold any responsibility for anybody breaking their equipment. You are doing this at your own risk : but hey for $39 who cares ![]() I have been reading upon this for a while now and I was reading one of max@remote-exploit papers where he had changed the firmware using the bluez utilities to make the dongle go into RAW mode or promiscuous mode. EDIT Seems I was a bit keen in this tutorial as it turns out this mod was not successful after all. The reason being that there are two types of bluecore-4 chipset, BlueCore-4 rom and BlueCore-4 external. The ROM chip has the firmware embedded on the chip and the EXT model has external memory for the firmware. You need to be able to update the firmware to allow sniffing in windows. To find out if you have the right type of chipset, type ........ Code:
hciconfig hci* revision Also it must be in promiscuous mode because we see bytes via hciconfig and RAW on the modes ??? I'm looking into this more at the moment so as I learn more I will add. First lets backup your old firmware with dfutool. Code:
dfutool -d hci0 archive backold.dfu Code:
hciconfig hci0 up ![]() Now we have have to hunt down the value of the USB product & vendor identifier. To get the product ID type Code:
bccmd psget -s 0x0000 0x02bf Code:
USB product identifier: 0x0001 (1) Code:
bccmd psget -s 0x0000 0x02be Now lets write the new IDCode:
bccmd psset -s 0×0000 0×02bf 0×0002 Code:
bccmd psget -s 0x0000 0x02bf Code:
USB product identifier: 0x0002 (2) Now from what I have read 9 times out of ten you don't need to change your vendor ID but check to see if its 0×0a12 if not change that to. Code:
bccmd psset -s 0×0000 0×02be 0×0a12 ![]() Code:
drgr33n ~ # hciconfig hci0
hci0: Type: USB
BD Address: 00:11:67:5A:A5:C8 ACL MTU: 0:0 SCO MTU: 0:0
UP RUNNING RAW
RX bytes:41281 acl:0 sco:0 events:0 errors:0
TX bytes:42532 acl:0 sco:0 commands:1971 errors:0
drgr33n ~ # hciconfig hci0
hci0: Type: USB
BD Address: 00:11:67:5A:A5:C8 ACL MTU: 0:0 SCO MTU: 0:0
UP RUNNING RAW
RX bytes:41293 acl:0 sco:0 events:0 errors:0
TX bytes:42535 acl:0 sco:0 commands:1972 errors:0
drgr33n ~ # hciconfig hci0
hci0: Type: USB
BD Address: 00:11:67:5A:A5:C8 ACL MTU: 0:0 SCO MTU: 0:0
UP RUNNING RAW
RX bytes:41305 acl:0 sco:0 events:0 errors:0
TX bytes:42538 acl:0 sco:0 commands:1973 errors:0
drgr33n ~ # hciconfig hci0
hci0: Type: USB
BD Address: 00:11:67:5A:A5:C8 ACL MTU: 0:0 SCO MTU: 0:0
UP RUNNING RAW
RX bytes:41317 acl:0 sco:0 events:0 errors:0
TX bytes:42541 acl:0 sco:0 commands:1974 errors:0
drgr33n ~ # hciconfig hci0
hci0: Type: USB
BD Address: 00:11:67:5A:A5:C8 ACL MTU: 0:0 SCO MTU: 0:0
UP RUNNING RAW
RX bytes:41329 acl:0 sco:0 events:0 errors:0
TX bytes:42544 acl:0 sco:0 commands:1975 errors:0
![]() Merry Christmas !
__________________
yada yada
Last edited by Dr_GrEeN; 12-22-2007 at 04:08 PM. |
|
||||
|
http://www.5min.com/Video/Eavesdropp...eadsets-925061
Funny Stuff. I was able to get most of this working, however, my headset was not vulnerable or something.
__________________
I felt like bending the bars back, and ripping out the window frames and eating them. yes, eating them! Leaping, leaping, leaping! Colonics for everyone! All right! You dumb*sses. I'm a mental patient. I'm *supposed* to act out! |
|
|||
|
Just as some side info, if you are using a logitech bluetooth adapter that came with your keybaord/mouse you may get an issue with the hciconfig hci0 up command. To remedy this, enter the commands...
hid2hci hciconfig hci0 up and last to make sure its up, hciconfig -a This probably doesn't apply to many people but oh well. (I had that problem though. Thanks google. )
Last edited by ESC201; 12-13-2007 at 03:52 AM. Reason: typo |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|